On October 1, 2026, DOJ’s National Fraud Enforcement Division (NFED) issued Directive 26-12: Corporate Enforcement in the Fight Against Fraud to all Fraud Division personnel. The Directive represents a significant escalation in DOJ's corporate enforcement posture. It deploys an all-tools framework for investigating and prosecuting fraud, requires centralized oversight of corporate cases from inception through litigation or resolution, establishes ten critical considerations for charging and plea decisions, and directs the Division to strengthen incentives for whistleblowers to report wrongdoing.
Enforcement Priorities
The Directive identifies four areas of focus for investigation, echoing the NFED’s memorandum on enforcement priorities released in August 2026 (see our alerts here and here):
Health care fraud: Health care fraud schemes, unlawful distribution of controlled substances, and violations of the Federal Food, Drug, and Cosmetic Act.
Public trust and financial integrity: Schemes involving procurement, government contracts, and other government functions that undermine public trust or the financial integrity of U.S. citizens and markets.
Internal revenue evasion: Significant evasion of internal or external revenue, including substantial tax-evasion schemes.
Trade and supply-chain misconduct: Tariff evasion, fraudulent importation of goods or services, and forced labor.
Factors in Charging and Resolution Decisions
When determining whether to charge a corporation or enter into a plea agreement or other resolution, the Directive instructs prosecutors to give “great weight” to ten enumerated factors. Those factors are intended to play a central role in charging and resolution decisions, although the Directive makes clear that the list is non-exclusive and that prosecutors may consider additional circumstances consistent with the Principles of Federal Prosecution of Business Organizations. The Directive further emphasizes that the Department-wide Corporate Enforcement and Voluntary Self-Disclosure Policy (“CEP”) applies in every corporate investigation, reinforcing the importance of timely self-disclosure, meaningful cooperation, and effective remediation when companies seek credit from the Department (see our alerts here and here).
Management knowledge of or participation in the misconduct;
Efforts to conceal fraud from regulators or obstruct government involvement;
Conduct lasting three years or longer;
Conduct threatening Americans’ safety or security, including military readiness;
Substantial financial hardship to a taxpayer-funded program or government function;
Conduct impacting multiple taxpayer-funded programs or government functions;
Conduct affecting three or more federal districts;
Financial harm to 25 or more victims, or losses of $25 million or more;
U.S. dollars moved abroad to support foreign adversaries; and
Immigration offenses.
Whistleblower Incentives and Data Analytics
The Directive places significant emphasis on identifying, protecting, and incentivizing whistleblowers, including culpable insiders, who provide information regarding corporate misconduct. It directs Division leadership to develop and implement new "policies and programs" designed to encourage whistleblowers to come forward and, to the extent possible, provide public transparency regarding those initiatives. The Directive also highlights the role of the National Fraud Detection Center, signaling the Division's intent to leverage advanced technology, data analytics, and other investigative resources to identify misconduct, generate leads, and accelerate the opening of new investigations.
These initiatives would supplement existing Department whistleblower efforts, most notably the Criminal Division's Corporate Whistleblower Awards Pilot Program (see our alerts here and here). Together, they reflect the Department's continuing commitment to expanding the use of whistleblower intelligence as a key source of corporate enforcement leads and increasing the incentives for insiders to report misconduct before it comes to the government's attention through other means.
Practical Takeaways for Companies
Assess and strengthen compliance programs. The Directive makes clear that DOJ will continue to closely evaluate a company's compliance program, internal controls, and corporate culture. Companies, particularly those operating in health care, government contracting, tax, and trade, should assess whether their programs are well designed, adequately resourced, and effective in practice. To that end, companies should consider updating their risk assessment process to address the NFED's stated enforcement priorities.
Reinforce whistleblower programs and reporting channels. Companies should ensure that internal reporting mechanisms are accessible, permit anonymous reporting, and are trusted by employees to raise concerns without fear of retaliation. Effective and responsive internal reporting systems may reduce the likelihood that employees bypass the company and report directly to DOJ, preserving the company's opportunity to identify issues first and evaluate potential self-disclosure. Companies should also provide regular anti-retaliation training and review confidentiality agreements, severance provisions, codes of conduct, and related policies to ensure they do not discourage or impede reporting to government authorities.
External Whistleblowers as a Compliance Risks. With DOJ, SEC, CFTC, and other agencies increasingly incentivizing external reporting through whistleblower award programs, companies should assume that employees, contractors, vendors, and other third parties may report concerns directly to the government before raising them internally. Companies should therefore ensure that reporting channels are accessible to employees and third parties alike, investigate complaints promptly, document remediation efforts, and maintain robust anti-retaliation protections. Effective intake and escalation procedures can increase the likelihood that concerns are identified and addressed internally before they become government investigations.
Decisions must be made earlier than in the past. Companies should consider engaging experienced outside counsel earlier than they may have in the past. The Directive's emphasis on rapid disclosure decisions, data-driven lead generation, and expanded whistleblower incentives increases the likelihood that DOJ may learn of potential misconduct before a company has completed its internal investigation. As a result, companies may face pressure to evaluate disclosure obligations and strategic response options before all relevant facts are known. Early involvement of outside counsel can help preserve privilege, accelerate fact-gathering, navigate the CEP's compressed timelines, and maximize available cooperation credit while the investigation is still developing. In short, the Directive places a premium on making informed decisions sooner and with less information than companies have historically had available.
Evaluate voluntary self-disclosure promptly. DOJ's data-driven lead generation capabilities and expanded whistleblower incentives increase the likelihood that the government may learn of misconduct before a company completes its internal investigation. Companies should therefore be prepared to evaluate voluntary self-disclosure considerations efficiently and effectively. This includes identifying decision-makers and escalation channels in advance and ensuring that critical investigative milestones can be met within the CEP's 120-day timeline.
Prepare for data-driven, multi-agency investigations. The Directive's emphasis on data analytics and coordination with law enforcement partners signals an increase in data-driven, multi-agency investigations. Because information may move quickly across agencies, a single issue may trigger parallel criminal, civil, administrative, and state proceedings. Companies should consider deploying data analytics tools and monitoring techniques similar to those being leveraged by the NFED to identify red flags in priority enforcement areas. Companies should also map relevant regulatory authorities, understand reporting obligations, and periodically test their response readiness.
Prepare for increased scrutiny of government contractors. Government procurement fraud is expressly identified as an enforcement priority. Government contractors should expect heightened scrutiny of certifications, billing practices, subcontractor relationships, cybersecurity and data-security obligations, small business program compliance, grants management, and performance-related representations to the government. Because issues identified through audits, hotline complaints, agency reviews, or civil False Claims Act investigations may now receive earlier and more coordinated criminal review, contractors should ensure robust compliance controls, investigate potential issues promptly, and carefully assess disclosure obligations to contracting agencies and DOJ.
Conclusion
The Directive transforms the NFED's enforcement priorities into a comprehensive corporate enforcement framework marked by centralized oversight, enhanced whistleblower incentives, data-driven investigations, and clearly defined aggravating factors that will shape charging and resolution decisions. For companies, particularly government contractors and those operating in other high-risk sectors, the message is clear: DOJ expects proactive compliance, rapid escalation of potential issues, and thoughtful consideration of voluntary self-disclosure. Organizations that strengthen compliance programs, foster trusted reporting channels, and prepare for increasingly sophisticated investigations will be better positioned to mitigate risk, obtain CEP credit where appropriate, and potentially avoid corporate criminal charges altogether.
Womble Bond Dickinson (US) LLP’s White Collar Defense and Criminal Investigations Team navigates domestic and international clients in all manner of white collar, regulatory, corporate and congressional investigations. Our team includes a distinguished roster of veteran defense attorneys, former federal prosecutors and U.S. Attorneys who served at the highest levels of the Department of Justice and at leading United States Attorneys’ Offices. Our team includes Chambers Ranked (Band 1) lawyers and alumni of the U.S. Department of Justice, the SEC’s Enforcement Division, the U.S. Senate, House of Representatives, and in-house compliance specialists of publicly traded companies.
You are switching to the United States
This selection will switch the website from presenting information primarily about the United Kingdom to information about the United States. If you would like to switch back, you may use location selection options at the top of the page.
Contact
Although we would like to hear from you, we cannot represent you until we know that doing so will not create a conflict of interest. Also, we cannot treat unsolicited information as confidential. Accordingly, please do not send us any information about any legal matter until we authorize you to do so. To initiate a possible representation, please call one of our lawyers or staff members.
By clicking the “ACCEPT” button, you agree that we may review any information you transmit to us. You recognize that, even if you submit information that you consider confidential in an effort to retain us, our review of that information will not create an obligation on us to keep it confidential and will not preclude us from representing another client directly adverse to you, even in a matter where that information could and will be used against you.
Please click the “ACCEPT” button if you understand and accept the foregoing statement and wish to proceed.